T06 · System Persistence
- Location
SKILL.md:76- Finding
Persistent Autonomous Execution Through Scheduled Agent Tasks
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent, but it directs recurring autonomous briefing delivery through external services without enough scoping, consent, or removal controls.
Review before installing. Use this only in a constrained workspace with least-privilege Feishu/Lark and messaging credentials, confirm recipients before any send, prefer one-time preview runs first, and create scheduled cron jobs only with an explicit expiration and a documented removal process.
SKILL.md:76Persistent Autonomous Execution Through Scheduled Agent Tasks
SKILL.md:8Unpinned Third-Party Dependencies and Browser Components
The skill description emphasizes automation and delivery but does not give a prominent warning that generated content may be uploaded to external services and sent to recipients. In context, this omission is material because the skill integrates with Feishu/Lark, voice generation, and cron scheduling, so users may invoke it expecting local content generation rather than external publication or recurring delivery.
The quick-start phrase is a natural-language request that could plausibly appear in ordinary conversation, making accidental invocation more likely. In this skill, accidental triggering is more dangerous than usual because execution can search external sources, generate content, and deliver outputs through Feishu/Lark with limited explicit warning at invocation time.
The second example is similarly broad and describes a common content-creation task without any constraint tying it to deliberate skill invocation. Because this skill can produce and distribute generated artifacts automatically, an ambiguous trigger increases the risk of unintentional execution, data egress, or message delivery to configured recipients.
No suspicious patterns detected.